From owner-freebsd-pf@FreeBSD.ORG Sun Sep 22 12:47:59 2013 Return-Path: Delivered-To: freebsd-pf@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [8.8.178.115]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTP id 0E786344 for ; Sun, 22 Sep 2013 12:47:59 +0000 (UTC) (envelope-from peter@bsdly.net) Received: from skapet.bsdly.net (unknown [IPv6:2001:16d8:ff00:1a9::2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mx1.freebsd.org (Postfix) with ESMTPS id B50042D38 for ; Sun, 22 Sep 2013 12:47:58 +0000 (UTC) Received: from sonofskinny.bsdly.net ([192.168.103.254] helo=deeperthought.bsdly.net) by skapet.bsdly.net with esmtp (Exim 4.77) (envelope-from ) id 1VNj4j-0007E7-FI; Sun, 22 Sep 2013 14:47:45 +0200 To: freebsd-pf@freebsd.org Subject: Re: Can we use ALTQ and PF to modify packets which acts as a bridge in my testing environment? References: From: peter@bsdly.net (Peter N. M. Hansteen) Date: Sun, 22 Sep 2013 14:47:43 +0200 In-Reply-To: (roshan david's message of "Sun, 22 Sep 2013 08:33:04 +0530") Message-ID: <8738oxoweo.fsf@deeperthought.bsdly.net> User-Agent: Gnus/5.1008 (Gnus v5.10.8) XEmacs/21.4.22 (berkeley-unix) MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 22 Sep 2013 12:47:59 -0000 roshan david writes: > Right now i am using dummynet and ipfw as my traffic shaper, I want to know > wheather ALTQ with PF can be used to modify packets,if yes what is the pf > ruleset to modify packet? It's not clear to me what it is you're tryint to achieve. PF with ALTQ is certainly capable of traffic shaping. The FreeBSD Handbook's PF part recently grew a bit, and it might even have material or references to point you in the right direction - http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/firewalls-pf.html and look for section "30.4.6 PF Rule Sets and Tools" - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network traffic" delilah spamd[29949]: 85.152.224.147: disconnected after 42673 seconds.